A good point about the VPN, but if you still need VNC advice, here it is.
If you are planning to use VNC for remote desktop support of these workstations, you don't need to port forward.
You can start the VNC viewer in Listen mode and give the user your IP address. The user starts the VNC server, right-clicks the icon, selects "Add new client", then enters your ip address. The viewer starts on your desktop. No port forwarding on the client side, and you don't need to remember their password.
Shawn